DEV Community

Mark0
Mark0

Posted on

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Citrix has confirmed the active exploitation of two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway, identified as CVE-2026-88771 and CVE-2026-88772. These flaws, both carrying a CVSS score of 9.5, allow unauthenticated attackers to execute arbitrary commands or cause denial-of-service conditions. CVE-2026-88771 is particularly dangerous as it affects all deployments regardless of configuration, while CVE-2026-88772 targets systems with DTLS enabled, which is often a default setting.

In addition to the exploited vulnerabilities, Citrix addressed six other flaws ranging from HTTP request smuggling to memory overflows. Since these vulnerabilities were exploited as zero-days before patches were released, security experts emphasize that simply updating may not be sufficient to remediate existing compromises. Organizations are urged to apply the latest firmware updates immediately and follow forensic procedures to check for indicators of compromise, such as preserving logs and rotating service credentials.


Read Full Article

Top comments (0)